
TintCal Security & Risk Analysis
wordpress.org/plugins/tintcalA beautiful and simple event calendar plugin for Japanese users. Add a calendar to any site with a shortcode, block, or widget.
Is TintCal Safe to Use in 2026?
Generally Safe
Score 100/100TintCal has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tintcal" v2.2.6 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and by incorporating a reasonable number of nonce and capability checks. The absence of known vulnerabilities in its history is also a strong indicator of a generally secure development process.
However, significant concerns arise from the static analysis. A substantial portion of the attack surface, specifically 8 out of 9 entry points, are unprotected by authentication checks. This means that if any of these AJAX handlers can be triggered by unauthenticated users, they could potentially be exploited. Furthermore, the taint analysis reveals one flow with unsanitized paths, which, despite not being flagged as critical or high severity, warrants attention as it indicates a potential for unexpected behavior or information leakage if exploited. The relatively low percentage of properly escaped output (43%) also suggests a risk of Cross-Site Scripting (XSS) vulnerabilities in the plugin's frontend or administrative interfaces.
In conclusion, while the plugin benefits from secure SQL handling and a clean vulnerability history, the high number of unprotected entry points and the presence of unsanitized paths in the taint analysis are notable weaknesses. These areas should be prioritized for review and remediation to strengthen the plugin's overall security.
Key Concerns
- 8 unprotected AJAX handlers
- Unsanitized path flow
- Low output escaping percentage (43%)
TintCal Security Vulnerabilities
TintCal Release Timeline
TintCal Code Analysis
Output Escaping
Data Flow Analysis
TintCal Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
TintCal Maintenance & Trust
Maintenance Signals
Community Trust
TintCal Alternatives
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
Events Calendar for GeoDirectory
events-for-geodirectory
Events Calendar add-on for GeoDirectory allows to extend your GeoDirectory powered website with a versatile event manager.
Events Calendar by AddEvent – Embeddable Event Calendar Plugin
addevent
Easily embed your events calendar on your WordPress site with AddEvent's embeddable calendar plugin.
Events Calendar Plus
events-calendar-plus
Display a beautiful events calendar with customizable views, coloring, filtering, date formats, images, and optimized for mobile on your own website.
TintCal Developer Profile
1 plugin · 10 total installs
How We Detect TintCal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tintcal/assets/css/admin.css/wp-content/plugins/tintcal/assets/css/frontend.css/wp-content/plugins/tintcal/assets/js/admin.js/wp-content/plugins/tintcal/assets/js/frontend.js/wp-content/plugins/tintcal/assets/js/vendor/moment.min.js/wp-content/plugins/tintcal/assets/js/admin.js/wp-content/plugins/tintcal/assets/js/frontend.js/wp-content/plugins/tintcal/assets/js/vendor/moment.min.jstintcal/assets/css/admin.css?ver=tintcal/assets/css/frontend.css?ver=tintcal/assets/js/admin.js?ver=tintcal/assets/js/frontend.js?ver=tintcal/assets/js/vendor/moment.min.js?ver=HTML / DOM Fingerprints
tintcal-admintintcal-event-datetintcal-holiday-datetintcal-weekdaytintcal-month-navtintcal-year-navdata-tintcal-iddata-tintcal-colordata-tintcal-labeltintcal_admin_paramstintcal_frontend_params[tintcal]